building-a-promotion-case

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFENO_CODEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill contains no executable scripts (Python, JavaScript, Shell) or platform-specific configuration commands that could be leveraged for malicious execution. It is composed entirely of educational Markdown content and instructions.
  • [EXTERNAL_DOWNLOADS]: The skill includes links to external templates and reference materials from reputable sources.
  • Evidence: References to Google Docs (docs.google.com), YouTube, and Lenny's Newsletter in references/artifacts.md and references/guest-insights.md are used for legitimate career templates and source material attribution.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided career details to generate professional documents, creating a standard surface for indirect prompt injection.
  • Ingestion points: User input describing business impact, wins, and testimonials (SKILL.md).
  • Boundary markers: Not present in the instructional text.
  • Capability inventory: The skill is limited to text generation; there is no evidence of tool usage (such as file writes or network requests) that could be exploited via injection.
  • Sanitization: None specified, which is common for purely instructional skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:06 PM
Security Audit — agent-trust-hub — building-a-promotion-case